CVE-2025-49188: Sensitive Data in URL
Published Jun 12, 2025
·Updated
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
Affected Software
1 affected component
SICK Field Analytics
Event History
Jun 12, 2025
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49188?
The severity of CVE-2025-49188 is rated as high with a score of 7.5.
2
What risks are associated with CVE-2025-49188?
CVE-2025-49188 exposes sensitive user credentials due to being sent as URL parameters, increasing the risk of information gathering.
3
How do I fix CVE-2025-49188?
To fix CVE-2025-49188, modify the application to send user credentials via POST bodies instead of URL parameters.
4
Who is affected by CVE-2025-49188?
CVE-2025-49188 affects users of the SICK Field Analytics application.
5
What is the potential impact of CVE-2025-49188?
The potential impact of CVE-2025-49188 includes unauthorized access to sensitive user credentials.